Browser shows “Not Secure” or certificate warning
1
Check expiration
Visit the site in a browser and click the padlock (or warning icon) to view certificate details. If expired, [renew immediately](/SSL & Website Security/contact-2-2-3).
2
Verify hostname match
The certificate must cover the exact hostname (
www.yourdomain.com vs. yourdomain.com). Wildcards cover only one level of subdomain.3
Confirm installation
Re-run installation in cPanel or on your server. Ensure the CA bundle is included.
4
Test with SSL Labs
Run ssllabs.com/ssltest for a full diagnosis and grade.
Mixed content warnings
Your page loads over HTTPS but includes HTTP resources (images, scripts, styles).1
Open browser console
Open Developer Tools > Console. Look for
Mixed Content warnings.2
Update resource URLs
Change all
http:// references in your HTML, CSS, and JS to https:// (or use protocol-relative //).3
Fix CMS URLs
In WordPress, update Site URL in Settings > General and use a plugin like Better Search Replace to update database URLs.
”Your connection is not private” (NET::ERR_CERT errors)
ERR_CERT_DATE_INVALID
Certificate is expired or the system clock is wrong.
ERR_CERT_COMMON_NAME_INVALID
Certificate doesn’t match the hostname. Reissue with correct domain.
ERR_CERT_AUTHORITY_INVALID
Missing or wrong CA bundle. Reinstall with the full chain.
ERR_SSL_PROTOCOL_ERROR
Server misconfigured or unsupported protocol. Update server config.
HTTPS redirect not working
1
Verify certificate is installed
Visit
https://yourdomain.com directly. If it works, the certificate is installed.2
Enable Force HTTPS in cPanel
Under Domains, toggle Force HTTPS Redirect on.
3
Check .htaccess
Confirm the rewrite rules haven’t been overwritten or commented out. See [Installing SSL](/SSL & Website Security/contact-2-2) for examples.
CA bundle or intermediate certificate missing
Symptom: the site works in desktop browsers but fails on mobile or older devices.1
Reinstall with the CA bundle
In cPanel SSL/TLS Manager, paste the CA bundle in the correct field.
2
Concatenate for Nginx
Combine your certificate and intermediates into one file:
cat yourdomain.crt ca-bundle.crt > fullchain.crt3
Restart web server
Reload Nginx or restart Apache to pick up the change.
Validation email not received
1
Check spam folder
Approval emails sometimes land in junk.
2
Use an approved address
Only certain addresses can receive validation (admin@, webmaster@, hostmaster@, or the WHOIS admin email).
3
Switch to DNS validation
In your order, change the validation method to DNS if email fails.
.png?fit=max&auto=format&n=dGkoxjFuwLusXp7Z&q=85&s=32c3cb11b5a290cd869640fca5093944)